Hi,
I have real problems at the moment with internal site to site traffic being picked up by the firewall DoS as being an attack
DrayTek 2920 192.168.16.x >to> DrayTek 2820 192.168.36.x VPN
The 2920 site hosts the domain controller, the 2820 site has 5 domain login and email clients...
The email report is as follows can anyone help
2011/02/25 07:56:14 -- [DOS][Block][ping_of_death][192.168.16.1->192.168.36.102][ICMP][HLen=20, TLen=1500, Type=0, Code=0]
2011/02/25 07:56:20 -- [DOS][Block][ping_of_death][192.168.16.1->192.168.36.102][ICMP][HLen=20, TLen=1500, Type=0, Code=0]
2011/02/25 07:56:25 -- [DOS][Block][ping_of_death][192.168.16.1->192.168.36.102][ICMP][HLen=20, TLen=1500, Type=0, Code=0]
2011/02/25 07:56:31 -- [DOS][Block][ping_of_death][192.168.16.1->192.168.36.102][ICMP][HLen=20, TLen=1500, Type=0, Code=0]
2011/02/25 07:56:36 -- [DOS][Block][ping_of_death][192.168.16.1->192.168.36.102][ICMP][HLen=20, TLen=1500, Type=0, Code=0]
2011/02/25 07:56:42 -- [DOS][Block][ping_of_death][192.168.16.1->192.168.36.102][ICMP][HLen=20, TLen=1500, Type=0, Code=0]
2011/02/25 07:58:27 -- [DOS][Block][trace_route][63.211.239.42:10905->83.218.10.235:33435][UDP][HLen=20, TLen=32]